cd /news/ai-agents/parameter · home topics ai-agents article
[ARTICLE · art-126389] src=parameter.ai ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Parameter

Parameter, a Y Combinator-backed security startup, launched a platform of AI agents that continuously find vulnerabilities in web apps, APIs, and infrastructure, claiming first findings within 24 hours and less than 1% false positives. The company says its agents have prevented more than $30 billion in breaches and pair autonomous pentesting with a pull-request reviewer called Sentinel, cloud misconfiguration checks, secrets detection, and dependency management. Parameter states its agents confirm a vulnerability and then stop, with no destructive actions and a full audit trail, positioning the product against traditional pentests that take weeks to scope and cost six figures per engagement.

read3 min views1 publishedSep 11, 2026
Parameter
Image: source

Backed by Y Combinator

AI agents that find vulnerabilities in your web apps, APIs, and infrastructure. Continuously, not once a year.

See first findings in 24 hours

$30B+

in breaches prevented

<1%

false positives

24/7

continuous coverage

Built by the team that secured:

Built by the team that secured:

[ the problem ]

Software ships every day.Security testing hasn't kept up. #

Old Way

Weeks to schedule

and scope.

Six figures per engagement.

A PDF that's already stale on arrival.

One snapshot, then blind for 12 months.

The Parameter Way

Point us at your app,

easy scoping.

Runs continuously,

on demand.

Every finding ships a working proof-of-concept.

Probes every hour, every day.

[ how it works ]

[ The product ]

Findings you can act on.Validated, prioritized, and ready to assign. #

Book a call

See first findings in 24 hours

Findings

Acme API pentest

ACME-142

SQL injection in /api/users search param

The search parameter on GET /api/users is concatenated directly into a SQL query without parameterization. An attacker can inject arbitrary SQL to read or modify data belonging to other tenants.

Reproduction

GET /api/users?search=' OR '1'='1 → 200 OK · returns all users across tenants

The vulnerable code interpolates the raw value into the WHERE clause in users-repository.ts:42.

Activity

Jordan Lee

created this finding

3d ago

Alex Rivera

changed status to In Progress

2d ago

Maya Chen

assigned this to Jordan Lee

1d ago

Add a comment...

Properties

Status

Open

Severity

Critical

Assignee

J

Jordan Lee

Rating

CWE

CWE-89

Deadline

Overdue · Jun 12

Locations

users-repository.ts:42 Open a fix PR

Create Linear Issue

Copy AI Instructions

Search findings

Open

21

In Progress

6

Fixed

15

Showing 1 to 25 of 47 findings

‹ Previous

Page 1 of 2

Next ›

[ coverage ]

One platform.Every layer of your security. #

Parameter runs continuously across your code, cloud, and dependencies, and puts everything it finds in one place.

Pentesting agent

Continuous, autonomous pentesting, with a working proof-of-concept for every finding.

Sentinel

An AI reviewer on every pull request. Catches vulnerabilities before they merge.

Cloud security

Continuous checks for cloud misconfigurations, exposed services, and takeover risk.

Secrets detection

Leaked keys, tokens, and credentials found across your repos and history.

Dependency management

Vulnerable and outdated packages flagged, with a clear path to safe versions.

More detail on each surface

Learn more

[ safety ]

Aggressive testing.Zero blast radius. #

All the findings of a real attack, none of the fallout.

learn more about safety

Confirm and hold

Agents prove a vulnerability exists, then stop. No chaining or escalation without your explicit go-ahead.

Scoped, never stray

Agents stay inside the targets you authorize. No wandering into systems that aren’t in scope.

No destructive actions

No dropped tables, no deleted data, no denial of service. Testing is safe against production by design.

Full audit trail

Every action an agent takes is logged and reviewable, so you can see exactly what happened.

Start testing today. #

A URL and credentials is all it takes.

First findings land within 24 hours.

── more in #ai-agents 4 stories · sorted by recency
── more on @parameter 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/parameter] indexed:0 read:3min 2026-09-11 ·